wp2shell-PoC

RCE chain proof-of-concept for CVE-2026-63030 & CVE-2026-60137

Visit wp2shell-PoC ↗ link: rel="ugc noopener"

wp2shell-PoC is a proof-of-concept demonstration of a remote code execution vulnerability chain affecting WordPress environments. It documents the exploitation pathway for two specific CVEs (CVE-2026-63030 and CVE-2026-60137).

This is research code published on GitHub for security awareness and testing purposes. The project provides technical details on how these vulnerabilities can be chained together to achieve RCE, intended for authorized security researchers and WordPress administrators evaluating their infrastructure risk.

Discussion